诚实性修复: API限流Retry-After(wait=60s)+断言 / purge定时接线(04:00 cron+actor+测试) / Channel表单校验(ref+rules+validate) / README PG数字513
This commit is contained in:
@@ -172,9 +172,15 @@ def test_render_autoprint_off(db, auth_client, tenant, warehouse, customer, prod
|
||||
|
||||
|
||||
def test_render_tenant_isolation(db, auth_client, tenant, other_tenant, warehouse, customer, product):
|
||||
from apps.core.models import TenantMembership
|
||||
|
||||
bill = _make_confirmed_bill(tenant, warehouse, customer, product)
|
||||
c2 = APIClient()
|
||||
refresh = RefreshToken.for_user(__import__("django").contrib.auth.get_user_model().objects.create_user("bob2", "pass12345"))
|
||||
bob = __import__("django").contrib.auth.get_user_model().objects.create_user("bob2", "pass12345")
|
||||
# bob2 must be *authorized* for other_tenant: the point of this case is that
|
||||
# a cross-tenant object lookup returns 404 (no existence leak), not 403.
|
||||
TenantMembership.objects.create(user=bob, tenant=other_tenant, role="member")
|
||||
refresh = RefreshToken.for_user(bob)
|
||||
c2.credentials(
|
||||
HTTP_AUTHORIZATION=f"Bearer {refresh.access_token}",
|
||||
HTTP_X_TENANT_ID=other_tenant.code,
|
||||
|
||||
Reference in New Issue
Block a user